<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw ctl chain questions for the community in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151513#M24831</link>
    <description>&lt;P&gt;Simply based on the screenshot of chains, not really.&lt;/P&gt;
&lt;P&gt;You may see the chains enabled for a particular feature, but if the policy is configured to bypass the blade, it will not be reflected here.&lt;/P&gt;
&lt;P&gt;You can use the fw monitor to see the traffic between specific sources and destinations through inspection points that cover most of the chain modules.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 16:30:17 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2022-06-22T16:30:17Z</dc:date>
    <item>
      <title>fw ctl chain questions for the community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151501#M24830</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Considering the attached screenshot I am curious to know what members of the community have as answers to these questions or comments on the questions as they stand:&lt;/P&gt;&lt;P&gt;1. Can you see how the traffic flows through the kernel?&lt;/P&gt;&lt;P&gt;2. Besides the Firewall, what other modules are engaged?&lt;/P&gt;&lt;P&gt;3. Can you tell if IPS is currently deployed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some knowledge of the kernel is assumed but not advanced technical knowledge.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 15:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151501#M24830</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-06-22T15:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain questions for the community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151513#M24831</link>
      <description>&lt;P&gt;Simply based on the screenshot of chains, not really.&lt;/P&gt;
&lt;P&gt;You may see the chains enabled for a particular feature, but if the policy is configured to bypass the blade, it will not be reflected here.&lt;/P&gt;
&lt;P&gt;You can use the fw monitor to see the traffic between specific sources and destinations through inspection points that cover most of the chain modules.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 16:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151513#M24831</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-06-22T16:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain questions for the community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151519#M24832</link>
      <description>&lt;P&gt;PSL is going to be active if you have any blade active above and beyond FW and VPN (e.g. IPS, App Control, URL Filtering).&lt;BR /&gt;enabled_blades will provide a more precise answer to 2 and 3.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 19:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151519#M24832</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-22T19:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain questions for the community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151521#M24833</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;That is true, and to see PSL (the kernel module) the command -- fw ctl debug -m | grep 'Modules' -- is a good command.&lt;/P&gt;&lt;P&gt;So,basically, question number 2 cannot be answered and the answer to question number 3 is No if only considering the output of the fw ctl chain command.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 19:19:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain-questions-for-the-community/m-p/151521#M24833</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-06-22T19:19:07Z</dc:date>
    </item>
  </channel>
</rss>

